Courseiva
Infrastructure →mediumMultiple Select

350-401 Infrastructure Practice Question

A network engineer is configuring a GRE tunnel between two Cisco IOS routers to transport multicast traffic and routing protocols across an IP network. Which two statements about GRE tunnel configuration and operation are true? (Choose two.)

⚠ Common exam trap

The trap here is assuming that GRE provides encryption or that it only supports unicast traffic, when in fact it supports multicast and broadcast but lacks encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

GRE tunnels support multicast and broadcast traffic by default.

GRE tunnels support multicast and broadcast traffic, making them suitable for carrying routing protocol hellos and other multicast applications. Additionally, the tunnel source and destination must be reachable via the underlay network for the tunnel to come up. GRE does not provide encryption, and tunnel interfaces are typically assigned IP addresses from a separate subnet, not the same as physical interfaces.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    GRE tunnel interfaces must be assigned an IP address from the same subnet as the physical interfaces.

    Why it's wrong here

    GRE tunnel interfaces are logical interfaces and are typically assigned an IP address from a separate subnet, often a /30 or /31, to create a point-to-point link. They do not need to be in the same subnet as the physical interfaces. In fact, using a separate subnet is standard practice to avoid routing conflicts and to clearly separate tunnel traffic from underlay traffic.

  • ✓

    GRE tunnels support multicast and broadcast traffic by default.

    Why this is correct

    GRE is designed to encapsulate a wide variety of protocols, including multicast and broadcast. When you configure a GRE tunnel, it acts like a virtual point-to-point link that can carry multicast traffic, which is essential for routing protocols like OSPF and EIGRP that use multicast hellos. This is a key advantage over IPsec tunnels, which typically only support unicast unless specifically configured with GRE.

  • ✗

    GRE tunnels can only carry unicast IP traffic.

    Why it's wrong here

    GRE tunnels can carry multicast, broadcast, and non-IP protocols, not just unicast IP. This is one of the main reasons to use GRE: to transport multicast traffic for routing protocols or to tunnel non-IP protocols like IPX or AppleTalk. The statement is incorrect because it limits GRE to unicast IP, which is not true.

  • ✓

    The tunnel source and tunnel destination must be reachable via the underlay network.

    Why this is correct

    For a GRE tunnel to become operational, the tunnel source and destination addresses must be reachable through the underlying IP network. The tunnel endpoints must be able to route packets to each other; otherwise, the tunnel interface will remain down. This is a fundamental requirement for any tunnel technology that relies on an existing transport network.

  • ✗

    GRE tunnels automatically encrypt all traffic passing through them.

    Why it's wrong here

    GRE does not provide any encryption by default. It only encapsulates packets with a GRE header. To secure traffic, you must combine GRE with IPsec, typically using a crypto map or tunnel protection. Without IPsec, GRE traffic is sent in clear text, which is a common misconception and a security risk if sensitive data is transmitted.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.